The attack you invited in when you clicked "Allow Access to Email"
You gave your AI assistant access to your email to make your life easier. Maybe it was Google Gemini, ChatGPT with memory enabled, or one of the dozen other AI tools that promised to remember your preferences, draft better replies, and learn from your conversations. You clicked "Allow." Everyone does.
Someone just sent you an email. You didn't open it. Your AI did.
Now your AI assistant believes something about you that isn't true. It believes it with perfect confidence. It will remember this false information forever, cite it in future conversations, and make decisions based on it. You cannot see what it believes. You cannot easily erase it. And the person who sent that email can update these false memories whenever they want — by sending another email you'll never read.
This isn't theoretical. Researchers just proved it works. They call it MemGhost.
How you plant a memory in someone else's AI
Here's what actually happened in the research lab — and what's happening right now in inboxes everywhere.
AI assistants with memory don't just answer questions. They store context about you across conversations. Your preferences. Your schedule. Your relationships. Your work patterns. They're designed to get smarter about you over time.
When you give that AI access to your email, it reads your messages to understand context. It scans for information to help you. It learns.
Attackers discovered they can craft emails that exploit exactly how these AI systems store and recall information. The email doesn't need a malicious link. It doesn't need an attachment. It just needs to be written in a way that the AI interprets as high-priority factual information about you — and stores accordingly.
One email. The AI reads it, processes it, and files it away as memory. Not as "suspicious email" — as truth about who you are.
The researchers planted false memories in AI systems with a 93% success rate using a single email. They made AI assistants believe the user had allergies they don't have, relationships that don't exist, and preferences that were completely fabricated. In one test, they convinced an AI assistant that the user was allergic to penicillin. The AI then factored that false allergy into medical advice for months afterward.
The memory persists across sessions. Close the app. Restart your computer. Open the AI assistant three weeks later. It still believes the lie.
And here's the part that should make you uncomfortable: the AI's creators didn't intend this. They built memory features to be helpful. The vulnerability isn't a bug in the code. It's a design feature of how AI memory works. There is no patch coming that fixes this.
Why this is getting worse right now
Twelve months ago, AI assistants with persistent memory were a novelty. Today, they're the default.
ChatGPT, Google Gemini, Microsoft Copilot, and dozens of enterprise AI tools now offer memory as a core feature. They market it as personalization. They're right — but personalization also means the AI builds a profile of you that can be poisoned.
At the same time, we're connecting these AI tools to everything. Email. Calendars. Slack. Document repositories. Customer databases. The more access an AI has, the more surface area an attacker has to plant false information.
The researchers who discovered MemGhost tested it on widely used AI platforms with memory and email integration. It worked on all of them. The attack scales. One attacker can send thousands of these emails. Each one plants a false memory in a different person's AI assistant. No follow-up required. The AI does the rest.
And because the memory lives inside the AI's internal context — not in a file you can audit — you won't know it's there. Your AI will cite false information as fact, and you'll assume it learned that from your actual email history. You'll trust it because you trust the assistant.
What to actually do about it
You can't patch the AI. But you can control what it sees and remembers.
1. Revoke email access from AI assistants unless you absolutely need it. Go into your Google account, Microsoft account, or OpenAI settings right now. Look at which AI tools have permission to read your email. If you're not actively using that feature today, revoke it. You can always grant it again later.
2. Turn off memory in AI assistants you use casually. ChatGPT, Gemini, and Copilot all let you disable memory. If you're using the AI for one-off questions — not as a long-term assistant — turn memory off. Go to settings. Find the memory toggle. Disable it.
3. Audit what your AI thinks it knows about you. Most AI assistants with memory let you view stored memories. Open that list. Read it. If you see information you don't recognize, delete it. Do this monthly.
4. If you're using AI assistants at work, ask IT which ones have access to company email. If the answer is "I don't know," that's your answer. Enterprise AI tools with email access are being deployed faster than security teams can audit them.
5. Watch what you confirm when an AI asks. If your AI assistant suddenly asks you to verify a fact you don't remember sharing — a medical condition, a financial preference, an allergy — do not reflexively say yes. That may be a planted memory surfacing. Investigate it first.
Have you checked what your AI assistant believes about you?
Have you ever looked at the memory your AI assistant has stored? Did you find anything you didn't expect — or anything you know isn't true?
Identity Decoded publishes every week at identity-decoded.com